Improper access control in WordPress - CVE-2025-58246
Published: October 7, 2025 / Updated: December 23, 2025
Vulnerability identifier: #VU116650
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-58246
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and gain unauthorized access to some restricted content.
Affected software
WordPress
Debian Linux
wordpress (Debian package)
Debian Linux
wordpress (Debian package)
How to mitigate CVE-2025-58246
Install updates from vendor's website.
WordPress - addressed in versions 4.7.31, 4.8.27, 4.9.28, 5.0.24, 5.1.21, 5.2.23, 5.3.20, 5.4.18, 5.5.17, 5.6.16, 5.7.14, 5.8.12, 5.9.12, 6.0.11, 6.1.9, 6.2.8, 6.3.7, 6.4.7, 6.5.7, 6.6.4, 6.7.4, 6.8.3
wordpress (Debian package) - update to 6.8.3+dfsg1-0+deb13u1
wordpress (Debian package) - update to 6.8.3+dfsg1-0+deb13u1